THREAT OPS › Threat News › CVE-2026-16028: Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table
CVE-2026-16028: Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table
<p>Posted by Robert Rothenberg on Sep 07</p>========================================================================<br /> CVE-2026-16028 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-16028<br /> Distribution: Protocol-HTTP2<br /> Versions: before 1.14<br /
Indicators of compromise
- CVE-2026-16028cve
- https://metacpan.org/dist/Protocol-HTTP2url
Original source: https://seclists.org/oss-sec/2026/q3/664